At Digital Control Room, security is central to our services. We recognise the critical role that the security research and vulnerability testing community plays in ensuring the safety of our services. Our Vulnerability Response Programme (VRP) is designed to facilitate collaboration with researchers about potential vulnerabilities in our systems, establish rules for vulnerability testing and provide a Safe Harbour for our VRP participants.
DCR uses HackerOne to manage and validate properly disclosed vulnerability reports.
If you believe you have discovered a security vulnerability in any of our products or services, we encourage you to submit a report while ensuring confidentiality at all times.
When you report a vulnerability to us, we commit to:
Testing activities conducted in accordance with the VRP are protected by a Safe Harbour, meaning that we will not take legal action against researchers who discover and report vulnerabilities in accordance with this VRP. If a third party takes legal action against you in connection with your activities conducted in accordance with our VRP rules, we will make it known that your actions were conducted in compliance with our VRP.
In operating this VRP, any failure or delay by us to exercise any of our rights and interests will not operate as a waiver of the same.
Additionally, should anyone violate our VRP rules, we will retain all of our legal and equitable rights and other remedies, including the rights to seek injunctive relief, specific performance and other equitable relief.
This VRP should not be interpreted as encouragement or permission to hack, penetrate or otherwise attempt to gain unauthorised access to our applications, systems or data. To avoid any confusion between good-faith reporting and a malicious attack, we ask that you:
When reporting vulnerabilities, please consider the attack scenario/exploitability, and security impact of the bug. Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, it will not be eligible for a reward.
Please note that ONLY the following addresses are in scope, and everything else is out of scope:
The following issues are considered out of scope: https://docs.hackerone.com/en/articles/8494488-core-ineligible-findings
This VRP operates exclusively through HackerOne, and rewards will only be given in conjunction with our HackerOne programme.
Our rewards are based on severity per CVSS (the Common Vulnerability Scoring Standard). When duplicate reports occur, we only award the first report that was received (provided that it can be fully reproduced). Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.
Please note these are general guidelines, and reward decisions are at our discretion.
info@digitalcontrolroom.com
+44 (0) 20 3836 8930